Skip to content

WebVigilante private beta

Privacy notice

To look for information exposed about you, WebVigilante has to hold some of your information. This is what it holds, why, who else can see it, how long it stays and how you get it back or get rid of it.

Version 2026-08-29.v1. Last updated 29 August 2026.

In short

  • Nothing is searched for until you have entered it and consented. No scan runs without that.
  • Your name, the places you give, your identifiers and the evidence behind findings are encrypted before they are stored.
  • Your information is not sold, and it is not shared for advertising. There is no tracker or third-party analytics on these pages.
  • You can download everything held about you as one file, from Settings, at any time.
  • You can delete your account from Settings. That removes the records and the stored evidence files with them.

Who this notice is from

WebVigilante is a private beta. It is invite only, it is not open to the public, and it is still being built.

The operating entity, its postal address and a published contact address for privacy questions are not yet settled, so this notice does not name them. They will be published here before WebVigilante is offered to anybody outside the beta. In the meantime, everything this notice describes as your right is something you can do yourself from Settings, without asking anybody: read the whole record, correct it, or delete it.

What WebVigilante holds about you

Your account. Your name, your email address, when you registered and when you confirmed the address.

The person you asked it to look for. First name, any middle name, last name, country and, if you give one, a city. These are encrypted at rest.

The identifiers you add. Email addresses, usernames, aliases, phone numbers, domains and locations, whichever of them you choose to enter. The value itself is encrypted. Alongside it, a one way fingerprint is stored, which is what lets the same identifier entered twice be recognised as the same one without reading the value back. A masked version, the form you see on screen, is stored so a surface can show you which identifier a result refers to without displaying it in full.

Your consent. When you gave it, and which version of the wording you agreed to.

Scans. When a scan ran, why it ran, which sources it selected, which of them completed, failed or were skipped, why a source was skipped, and how many results each returned.

Findings. What was found, where, the address it was found at, a summary, the category and type, the severity and the rules that produced it, the confidence and the reasons behind it, when it was first and last seen, and what you decided about it.

The evidence behind a finding. The sighting a claim rests on: when it was observed, by which source, at which address, what part of your details matched, an excerpt, and how it was classified and why. Excerpts and matched values are encrypted at rest.

Captured proof. Where a copy of a page has been kept, the file is held on a private disk that is not reachable from the web, and the record of it keeps the type, the size, a checksum and whether the bytes are still held or have been destroyed.

Your protection history. What you planned to do, the steps you worked through, the cases you opened, every change of state on them with its time and reason, the rechecks that are booked, and what WebVigilante has told you and whether you have seen it. This history is append only: entries are added, never rewritten, because a record that can be edited is not a record of what happened.

Your preferences. Whether you have asked for a daily summary.

Technical records. A session cookie so you stay signed in, a token on each form that blocks cross site submissions, and ordinary server logs. Logs carry masked values, hashes and reason codes. A raw email address, phone number, name or identifier is never written to a log.

What it never holds

  • No credentials of any kind. No passkey, session cookie from another site, recovery code, security seed or provider token. Your own password is never stored: only a one way hash that can check a password without revealing it.
  • No exposed passwords. Where breach data includes a password, it is not stored, and no credential is ever tested against any service.
  • No copy of a leaked dataset. WebVigilante keeps references, masks, hashes and reasons, not whole dumps.
  • No advertising or analytics profile. Your information exists to show you your own exposure, and is used for nothing else.

Who else sees it

Your records sit on the machine that runs WebVigilante, in a database only this application can reach, with the sensitive fields encrypted. One account can never reach another account's data.

Finding information about you sometimes means asking somebody else, and where a search you have authorised requires it, an external provider may process the identifier being searched for and return results about it. A provider is given what that search needs and nothing more. No provider is given your records to keep, and none is paid in data.

These external providers are enabled today, and may process what a search you authorised requires:

  • hibp: Checking whether an address of yours appears in a known breach record.

That list is produced from the configuration this installation is actually running, not written into this page by hand, so it cannot name a provider that receives nothing or leave out one that does.

Account email is delivered by Mailgun. Confirming your address and resetting your password are messages that have to reach you, so the delivery service receives your email address and the contents of that message. It is given nothing else: not your identity data, not your findings, and not your protection history. Messages are sent through api.eu.mailgun.net, which is the regional endpoint this installation is configured to use.

Nothing is ever sent to a website, a data broker or any other third party on your behalf. WebVigilante does not contact anybody for you. Where something has to be sent, you send it, and the terms explain that division.

Email

Your email address identifies your account, confirms that the address is yours and lets you reset your password. It is not used for marketing, and it is not passed to anybody.

Sending is currently switched off on this installation. You can ask for a daily summary and the request is recorded, but while sending is off the summary is prepared and held rather than delivered. Nothing is sent to somebody who has not asked for it, and nothing is treated as delivered when it was not.

Consent, and why any of this is lawful

Processing your identity data rests on your consent. Before anything is searched for, you tick a box that says, in these words:

I am asking WebVigilante to monitor information about me and the identifiers I provide.

The consent currently in force is version 2026-08-26.v1. Your consent is stored with the version you agreed to, so consent given to older wording is never silently treated as agreement to new wording. If the wording changes, you are asked again.

Running your account, keeping you signed in and keeping the records you asked for rests on providing the service you registered for. Keeping the application secure, and keeping logs that carry masked values rather than identifiers, rests on the legitimate interest of running it safely.

Withdrawing consent: today the way to withdraw it is to delete your account, which removes the records rather than merely stopping new searches. A separate control that stops future scans while keeping your history has not been built, and this notice will not describe one until it exists.

How long it is kept

Your records are kept while your account exists. There is no fixed retention schedule yet: setting one is a decision that has not been made, and this notice will say what it is when it has been, rather than quoting a period nothing enforces.

Captured proof can be destroyed separately from the record it belongs to. When that happens the record keeps the fact that proof existed, was held and was destroyed, along with the date, because that is a truer answer to what happened to it than a row that quietly disappears.

Deleting your account is not a schedule. It happens when you ask for it, and it takes the stored evidence files with it.

Your rights, and how to use them today

  • See everything. Settings has an export. It gives you one machine readable file containing your account, the people you asked to be looked for, the identifiers you gave, every scan, every finding with its evidence and provenance, your whole protection history and everything WebVigilante has told you. It says in the file what it leaves out and why. It is built on the spot, sent once and never written to disk, and asking for it changes nothing in your records.
  • Take it elsewhere. That same file is structured data you can keep or hand to somebody else.
  • Correct it. Your account details are editable in Settings, and the details you asked to be looked for are editable on your own page.
  • Delete it. Settings has an account deletion that asks for your password and then removes the account, the records underneath it and the stored evidence files.
  • Object to a result. Marking a finding as not you is recorded and respected, and it stays out.
  • Complain. If you are in the EU or the UK, you can complain to your national data protection authority. You do not have to go through us first.

The export and the deletion both ask for your password, even though you are already signed in. Everything else in the product happens one exposure at a time; those two are the whole of it at once, so a borrowed session should not be enough.

How your records are held

  • Names, cities, identifier values, matched values and evidence excerpts are encrypted in the database.
  • Duplicate detection uses one way fingerprints, so recognising an identifier again does not require reading it back.
  • Every listing and every record is scoped to the account that owns it, and that boundary is tested on every surface.
  • Captured proof is stored on a private disk. There is no address that hands the file to anybody who has not signed in as its owner.
  • Logs carry masked values or hashes, never a raw identifier.
  • These pages load nothing from a third party, so nobody else learns that you visited them.

Cookies

WebVigilante sets a session cookie so that you stay signed in, and a token that stops another site submitting a form as you. Both are necessary for the application to work at all. There is no advertising cookie, no analytics cookie and no third party cookie.

Changes to this notice

This notice carries a version. When it changes materially the version changes with it. Where a change affects what you consented to, you are asked to consent again rather than assumed to agree.

What this notice does not yet say

A beta that is honest about its product should be honest about its paperwork. These are decided before WebVigilante is offered outside the private beta, and they are open now:

  • The operating entity, its address, and a published contact for privacy questions.
  • A retention schedule, with a period for records and one for captured proof.
  • A minimum age for using the service.
  • The named external providers, once any are enabled and their processing terms are accepted.

Until each of those is settled, this notice leaves it blank rather than filling it in with something that sounds right.

The terms

What WebVigilante does and does not do, and what a result means, are set out in the terms of use.